PT-2020-10286 · Ixp · Ixp Easyinstall
Published
2020-01-23
·
Updated
2020-01-29
·
CVE-2019-19893
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IXP EasyInstall version 6.2.13723
Description
The issue allows an unauthenticated attacker to perform Directory Traversal on the Engine Service via TCP port 8000. This enables access to the server's filesystem with the access rights of NT AUTHORITYSYSTEM.
Recommendations
For IXP EasyInstall version 6.2.13723, consider restricting access to the Engine Service on TCP port 8000 until a patch is available. As a temporary workaround, limit the access rights of the NT AUTHORITYSYSTEM to minimize potential damage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ixp Easyinstall